CVE-2026-104286: 
Fortimail Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-104286 is a critical path traversal vulnerability (CWE-22) in Fortinet FortiMail that allows unauthenticated remote attackers to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. The vulnerability also involves improper neutralization of NULL byte or NULL character (CWE-158). Affected versions include FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1. Disclosed on October 1, 2026, it was simultaneously added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation. It carries a CVSS v3.1 base score of 9.8 (Critical) (FortiGuard Advisory, CISA KEV, GitHub Advisory).

Detalhes técnicos

The vulnerability stems from insufficient validation of user-supplied path components in HTTP/HTTPS request handling within FortiMail's IBE (Identity-Based Encryption) feature, classified as CWE-22 (Path Traversal) and CWE-158 (Improper Neutralization of NULL Byte). An unauthenticated attacker can craft HTTP or HTTPS requests containing path traversal sequences (e.g., ../ or NULL byte-encoded variants) to escape the restricted web root and write arbitrary files to sensitive locations on the underlying operating system. No authentication or user interaction is required, and the attack is fully network-accessible with low complexity. The attack chain progresses from arbitrary file write to code execution, as evidenced by post-exploitation artifacts including a dropped shared library (/data/lib/liblog.so) and a modified ld.so.preload file (FortiGuard Advisory, GitHub Advisory).

Impacto

Successful exploitation enables an unauthenticated attacker to write arbitrary files anywhere on the FortiMail system, which in observed attacks has led to full system compromise including deployment of backdoors, web shells, and malicious shared libraries. The confirmed impact includes unauthorized code execution, potential exfiltration of email data and credentials processed by the mail gateway, and service disruption. Given FortiMail's role as an email security gateway, compromise could also facilitate interception of sensitive communications and lateral movement into internal networks (FortiGuard Advisory, CISA KEV).

Exploração

CVE-2026-104286 is actively exploited in the wild as a zero-day and was added to CISA's KEV catalog on October 1, 2026, with a remediation due date of October 4, 2026 — an unusually short window reflecting the severity of active exploitation (CISA KEV). Exploitation has been reported by watchTowr and BleepingComputer, with Fortinet confirming in-the-wild exploitation in its advisory (FortiGuard Advisory, BleepingComputer). The NVD SSVC assessment classifies exploitation as "active" and the vulnerability as "automatable," indicating it can be exploited at scale without manual intervention. No public proof-of-concept code has been confirmed, but the vulnerability is being weaponized by unknown threat actors. The EPSS score is currently 0.0 (newly published), though active exploitation makes this a high-priority remediation target (GitHub Advisory).

Etapas de exploração

  1. Reconnaissance: Identify internet-facing FortiMail instances using tools like Shodan or Censys, filtering for FortiMail web interfaces (typically on ports 443/80). Confirm version via HTTP response headers or login page banners to identify vulnerable versions (7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, 8.0.0–8.0.1).
  2. Craft malicious HTTP request: Construct a crafted HTTP or HTTPS request targeting the IBE (Identity-Based Encryption) feature endpoint, embedding path traversal sequences (e.g., ../../) or NULL byte characters to escape the restricted directory context.
  3. Arbitrary file write: Submit the crafted request to write a malicious file to a sensitive system location — in observed attacks, attackers wrote a malicious shared library to /data/lib/liblog.so and modified /data/etc/ld.so.preload to force its loading.
  4. Achieve code execution: The injected shared library is loaded by system processes via the modified ld.so.preload, granting the attacker persistent code execution on the FortiMail appliance.
  5. Establish persistence: Deploy additional backdoors such as /data/bin/webconsole or /data/bin/mailservice, and modify httpd.conf to maintain access. Configure data exfiltration via archive accounts pointing to attacker-controlled infrastructure (e.g., 79.141.169.187) (FortiGuard Advisory).

Indicadores de compromisso

  • File System:
    • [ADDED] /data/lib/liblog.so — MD5: 64c90a00c7fda4d5c7973ed64c25783a, SHA256: 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84
    • [MODIFIED] /bin/smit — MD5: 5241738a3e9988404239e12243f6d35b, SHA256: 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a
    • [ADDED] /data/bin/webconsole — MD5: ae0ea6502d3fa5f0664bceb73189eb54, SHA256: 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38
    • [ADDED] /data/bin/mailservice — MD5: f90fa81a5f521d785f2b2f765e3ab897, SHA256: 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b
    • [MODIFIED] /data/etc/httpd.conf — MD5: 61af1c4bce1c2eebc8ff689ca5337791, SHA256: 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5
    • [ADDED] /data/etc/ld.so.preload — MD5: 8eb64f25d2a8e18e05aae058629473cf, SHA256: 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6
    • [MODIFIED] /data/migadmin.tar.gz — MD5: 49a7156a7d043cc8f9f680579db22f86, SHA256: d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3
  • Network:
    • Outbound connections to 79.141.169.187 (attacker-controlled archive/exfiltration server)
    • Outbound connections to 45.129.0.192
    • Unusual HTTPS POST requests to IBE-related endpoints with path traversal sequences in parameters
  • Logs:
    • type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ..." — indicates cron-based persistence
    • type=kevent subtype=config ... msg="Added 'archive234' to 'archive account' ... remote-ip[79.141.169.187]" — unauthorized archive account creation pointing to attacker IP
    • type=kevent subtype=admin ... action=logout status=success reason=unknown msg="User admin logged out from (null)." — anomalous admin session activity
    • FortiMail IBE decryption errors: FortiMail::IBE::DecrypterMediaIn ... Caught BufferException(2) ... Invalid Base64 Encoding — may indicate exploitation attempts
    • Internal user *@domain.tld failed to log in — potential credential probing (FortiGuard Advisory)

Mitigação e soluções alternativas

Fortinet has released patched versions and organizations should upgrade immediately: FortiMail 8.0 → 8.0.2 or later; FortiMail 7.6 → 7.6.7 or later; FortiMail 7.4 → 7.4.9 or later; FortiMail 7.2 → upgrade to branch 7.4 or above (no 7.2.x patch available). As an immediate workaround, disable the IBE feature via CLI: config system encryption ibe → set status disable → end. Alternatively, restrict or block internet access to the FortiMail management interface, limiting access to trusted private networks only. CISA's BOD 26-04 requires federal agencies to apply mitigations by October 4, 2026, and also mandates forensic triage of potentially compromised systems (FortiGuard Advisory, CISA KEV).

Reações da comunidade

Fortinet's PSIRT published advisory FG-IR-26-175 on October 1, 2026, confirming active exploitation and urging immediate mitigation (FortiGuard Advisory). BleepingComputer reported on the zero-day attacks, generating significant community discussion on Reddit (r/SecOpsDaily), Mastodon, and Bluesky (BleepingComputer). Security researchers at watchTowr published an FAQ on the vulnerability, and runZero published a blog post on detection and asset identification. The CISA KEV tracker Mastodon account flagged the addition immediately, and the security community broadly characterized this as a high-urgency incident given the three-day remediation window imposed by CISA's BOD 26-04.

Recursos adicionais


Origem: Este relatório foi gerado usando IA

Relacionado Fortimail Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-104286CRITICAL9.8
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
SimNãoOct 01, 2026
CVE-2025-53681HIGH7.2
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NãoSimMay 12, 2026
CVE-2025-54972MEDIUM4.3
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NãoSimNov 18, 2025
CVE-2024-47569MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortimail
NãoSimOct 14, 2025
CVE-2025-55717MEDIUM4
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NãoSimMar 10, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades